An approach for exploiting and mitigating Log4J using Log4Shell vulnerability

Keshav Kaushik, Alpana Dass, Ayush Dhankhar · 2022

A new serious flaw has been discovered in log4j, a popular open-source tool used to produce logs within Java programs. The Log4Shell vulnerability, also referred as CVE-2021-44228, enables Remote Code Execution (RCE), enabling attackers to run obfuscated code on the host. A large number of programmes and businesses, including the well-known game Minecraft, employ the well-known utility log4j. Additionally, it is utilised in numerous commercial products as well as several Apache frameworks including Struts2, Kafka, Druid, and Flink. In this paper, the authors have used an approach to exploit the Log4Shell vulnerability and then provided the mitigation methods for the same.

Read the paper · More papers on PaperTik